reactive-resume
reactive-resume
A one-of-a-kind resume builder that keeps your privacy in mind. Completely secure, customizable, portable, open-source and free forever. Try it out today!
Mars-Sea/dsh-commandcode-provider
Command Code provider plugin for DeepSeek Harness (dsh). Adds Command Code model access, live model catalog, plan-aware model selection, reasoning effort, image input, web search, and multi-account support.
PROJECT TOPICS
INSTALL REFERENCE
dsh plugin --profile web add github:Mars-Sea/dsh-commandcode-provider
该命令指向仓库当前默认分支;尚无绑定当前 commit 的完整验证结果。
PROJECT README
English | 简体中文
Unofficial DeepSeek Harness LLM provider plugin for Command Code, ported from pi-commandcode-provider (MIT).
This is a community integration. You need your own Command Code account and API key or subscription, and Command Code's terms apply. This project is not affiliated with Command Code, Inc.
dsh plugin add; registers a commandcode provider route with a live model catalog./settings → Command Code page for the API key and the model controls.cmd login runs) from the settings page; the approved key lands in the local credential service automatically. Manual paste remains the fallback.FREE badge, peak/off-peak state, image support, and context window; free models listed first.≈) beside the composer token counter and in its usage dialog, using each request's model, request time and context tier from durable session history. Model switches and viewing the session later do not reprice earlier requests. Mixed-provider or unpriced usage shows a labeled subtotal (≥); missing history or wholly unpriceable usage stays hidden. These are estimates from the installed price snapshot, not provider invoices. Also English on every harness language.web_search tool is backed by the Command Code Provider API (/alpha/web-search) with the same key/endpoint as chat, so no separate search key or base URL is needed. See Web search.See Screenshots below for what the UI looks like.
This release supports dsh 0.2.1-alpha.1 and nothing else — the plugin's peer range is that one version, and its compatibility record names it alone:
dsh plugin --profile web add @mars-sea/dsh-commandcode-provider@latest
Older dsh releases. The 0.1.2–0.1.7 line is no longer supported: those
engines predate the 0.1.7 settings rewrite, the RequestMessage envelope, and
the durable image-offload contract, and the compatibility code that bridged
the two was removed. The last plugin release covering 0.1.7 is 0.11.17; the
0.1.2–0.1.6 line's last release is 0.11.11; the 0.5.0-era Harness line's last
release is 0.9.1. All are installed by exact version and none is maintained:
dsh plugin --profile web add @mars-sea/dsh-commandcode-provider@0.11.17 # dsh 0.1.7
dsh plugin --profile web add @mars-sea/dsh-commandcode-provider@0.11.11 # dsh 0.1.2–0.1.6
dsh plugin --profile web add @mars-sea/dsh-commandcode-provider@0.9.1 # dsh 0.5.0 line
pnpm 11 holds back new releases. Its minimumReleaseAge defaults to 1440 minutes, so a version published less than a day ago is skipped and @latest resolves to the previous release — silently, with a success exit code. To install a release from the last 24 hours, name it exactly:
dsh plugin --profile web add @mars-sea/dsh-commandcode-provider@0.11.15
The same applies to every profile you install into, including the terminal UI below.
Fresh pnpm 10 marketplace generations are supported directly. Every Harness package — including @deepseek-ai/cordis and @deepseek-ai/schemastery — is declared by the plugin at an exact version as a Host peer, so the active dsh profile remains their owner; do not add a separate dependency for any of them. Upstream removed the @deepseek-ai/dsh-invariants package in 0.2.1-alpha.1, so the plugin no longer declares it.
Update with the same tag you installed with:
dsh plugin --profile web update @mars-sea/dsh-commandcode-provider@latest # dsh 0.2.1-alpha.1
dsh plugin --profile web update @mars-sea/dsh-commandcode-provider@0.9.1 # older dsh (0.5.0 line, unmaintained)
Each profile updates separately — the terminal UI owns its own plugin list (see below):
dsh plugin --profile dsh-tui update @mars-sea/dsh-commandcode-provider@0.11.15
To move to a version published less than 24 hours ago, name it exactly as in Install above; pnpm 11's age gate resolves @latest to the previous release instead.
Then restart the web app.
The easiest path is the official CLI (Node.js 22+):
npm i -g command-code@latest
cmd login # macOS/Linux; native Windows: cmdc login
Or skip the CLI: click Sign in to Command Code under Settings → Command Code — your browser opens the commandcode.ai authorization page (the same flow cmd login uses) and the key is stored in the local credential service when you approve. You can still create a key on the Keys settings page and paste it into Settings → Command Code, or export COMMANDCODE_API_KEY="user_...".
The sign-in flow needs the Host and your browser on the same machine (loopback callback). With a remote Host, paste the key manually; a literal composition-level
apiKey, if set, still takes precedence over a signed-in credential.
After restart, enter your API key in Settings → Command Code and save; Settings → Models shows a Command Code card, and the model picker lists the live catalog under commandcode. Send a message with a model your plan includes.
The plugin also works under a terminal front door. Each dsh profile owns its own plugin list, so the web install above does not reach the terminal — add the plugin to the dsh-tui profile as well:
dsh plugin --profile dsh-tui add @mars-sea/dsh-commandcode-provider@0.11.15
Pin the exact version here. For the first 24 hours after a release, a bare package name (or @latest) is silently resolved to the previous one: the install succeeds, but the profile gets the older build — which is how a fresh terminal install ends up with no /settings → Command Code page and no commandcode models at all.
Then pick the provider in the model selector, or name it directly:
/model commandcode/deepseek/deepseek-v4.1-flash
/model lists every registered provider, with Command Code's live catalog and its plan/deal/context annotations. The /commandcode usage dashboard works there too.
Entering the key. The TUI has no web Models page, so the plugin declares its own page in the TUI settings screen — /settings → Command Code — with the API key, the API base, the out-of-plan model filter, the active account, and the command language. The key field is write-only: it shows whether a key is configured and writes what you type to the credential store, never to a settings document. The same page is the only place a TUI-only user needs to visit.
Picking models. That page lists the whole catalog as checkboxes, grouped by plan tier (Go → GOAT → Pro → Provider) with the free models first, so nothing has to be typed from memory. Everything starts checked, because an unset allowlist means "show every model" — uncheck the ones you do not want in the picker. The choice is stored as per-model overrides next to the visibleModels list the web page edits, so both surfaces can be used interchangeably and a plain visibleModels written by hand still works.
Alternatively, set the key outside the TUI — any of these work, in this order of precedence:
export COMMANDCODE_API_KEY="user_..." # launching environment
cmd login # writes ~/.commandcode/auth.json
Making Command Code the default. dsh-TUI pins its own agent route, and its agent-default-model setting does not override it. To start every session on Command Code, override the agent-loop row in your profile patch ($DSH_HOME/profiles/dsh-tui/cordis.patch.yml):
- id: agent-loop
inject: [tuiStartup]
config:
agents:
- id: main
provider: commandcode
model: deepseek/deepseek-v4.1-flash
reasoningEffort: max
cwd: !!js process.cwd()
Engine version. The plugin is maintained against exactly one engine: dsh 0.2.1-alpha.1. Its @deepseek-ai/dsh-* peers use the exact version 0.2.1-alpha.1, @deepseek-ai/cordis is pinned to ~4.0.5-alpha.1 and @deepseek-ai/schemastery to ~3.18.5-alpha.1 (all three released with that engine), and dsh.compatibility.dshReleases records that single release. Adjacent prereleases and stable patch versions have not been verified. Note that 0.2.1-alpha.1 is an early alpha, so it is less stable than the 0.2.0-rc.2 release candidate it replaces. On an older engine the settings page, the message envelope, or the request-image budget will not line up — install the last release that supported your engine (see Install) instead of forcing this one.
The plugin registers a /commandcode slash command showing per-account usage:
/commandcode (or /commandcode status)
The command's user-facing copy follows the shell's locale: explicit lang: 'en' | 'zh' in the llm-commandcode plugin config wins, otherwise LC_ALL/LANG is read, otherwise it falls back to zh. The web settings page is independent — it follows the browser's language preference on its own.
With several Command Code subscriptions, the plugin switches to the next account automatically when one hits its usage limit:
default account.modelAccountRules.)/commandcode reports the same per-account state.The equivalent YAML ($DSH_HOME/settings.yaml or composition config):
llm-commandcode:
apiKeyEnv: COMMANDCODE_API_KEY # first (default) account
activeAccount: COMMANDCODE_API_KEY_2 # optional: pin the active account (`default` or an account's credential ref)
accounts: # rotation order after it
- label: Go #2
apiKeyEnv: COMMANDCODE_API_KEY_2
- label: Go #3
apiKeyEnv: COMMANDCODE_API_KEY_3
modelAccountRules: # optional: route models to accounts (first match wins)
- models: # catalog model ids (multi-select)
- deepseek/deepseek-v4-pro
- deepseek/deepseek-v4-flash-vision-exp
account: COMMANDCODE_API_KEY_2
- models:
- tencent/hy4-preview
account: default
visibleModels: # optional: show only these models in pickers (catalog model ids); unset shows all
- deepseek/deepseek-v4-pro
- tencent/hy4-preview
Settings → Command Code is organized as Accounts (keys, sign-in, live quota, pinning, dedicated models), Models (hide out-of-plan models, visible models), Privacy & security (zero data retention, off by default, see below), Integrations & display (serve web search with Command Code, show the quota card in the sidebar, off by default), and a collapsed Advanced section (API base URL, request/stream timeouts, transport retries, cache-aware image offload). The working directory is no longer on the page; workingDir in config still works.
The same options live in $DSH_HOME/settings.yaml (changes apply immediately, no restart):
llm-commandcode:
apiKeyEnv: COMMANDCODE_API_KEY # credential reference
apiBase: https://api.commandcode.ai
workingDir: /path/to/project # optional
modelsCachePath: ~/.commandcode/models-cache.json
requestTimeoutMs: 300000 # default 300s (the official CLI's own budget)
streamIdleTimeoutMs: 300000 # default 300s
# offloadSeenImagesForCache: true # opt in to CLI cache mitigation; later requests omit old pixels
showSidebarQuota: true # optional: show the plans & quota card in the sidebar (default off)
zdr: true # optional: route requests only through zero-data-retention upstreams (default off)
On the CLI transport (/alpha/generate), a new image can make Command Code's reported prompt cache retreat to the first historical image even when every previous request message is byte-identical. The opt-in Stop replaying images already seen setting (offloadSeenImagesForCache) asks dsh's durable image/offload surface to replace an older image with a stable text placeholder after this same model has answered with it. The next request keeps its new image; later text can be cached without replaying old pixels. The default is off because the model cannot inspect an offloaded image again unless it rereads the source file or the user reattaches it. This mitigates the observed cost spike; it does not repair Command Code's underlying multimodal cache behavior. Live evidence and limits.
When your deployment's dsh shell mounts the web capability (@deepseek-ai/dsh-web + @deepseek-ai/dsh-tool-web), the model's web_search tool is served by this plugin's commandcode search provider — it calls the Command Code Provider API's /alpha/web-search endpoint with the same API key and base URL as chat. You do not configure a separate search key, endpoint, or model.
On by default. The plugin's Settings → Command Code page has a "Serve dsh web search with Command Code" toggle (webSearch, default on). When on, the plugin selects commandcode as the active search backend automatically; turn it off to hand the selection back to whichever backend was there before (a sibling search plugin such as modsearch keeps working — it is never forced back to dsh's shipped DeepSeek search). The toggle takes effect on the next search — no restart needed.
commandcode on ctx.web only when the web service is present; without it this stays a chat-only plugin.commandcode in the web seam at boot and on every settings change, remembering the backend it displaced; turning the toggle off (or unloading the plugin) restores that backend. If you'd rather pin it durably, set searchProvider: commandcode (or $DSH_WEB_SEARCH_PROVIDER=commandcode); that remains effective even if this plugin's runtime selection is unavailable.numResults from the dsh tool is clamped to the Command Code range (1–10, default 5); results map to the dsh WebSearchSource shape (url/title/snippet).This reuses the Command Code Provider API directly (like the official CLI's built-in
web_search), so it is distinct from a DeepSeek-native search backend.
Command Code can serve a request only through upstreams that retain no prompts or completions and never train on them — the same opt-in the official CLI exposes as CMD_ZDR=1, and the x-cmd-zdr: 1 header on the Provider API (official docs).
Off by default. Turn it on with the "Zero data retention (ZDR)" toggle (zdr) in the Privacy & security card, or in your profile config. How this plugin implements it:
KNOWN_NON_ZDR_MODELS, synced from the official CLI — 23 models as of 2026-09-29, e.g. xai/grok-4.5, stepfun/Step-3.7-Flash, meta/muse-spark-1.3). A model without an available ZDR upstream fails with 422 cmd_zdr_no_providers; the request is never retried without the header.Image or remove the images first.stop sequences — requests carrying one fail./provider/v1/chat/completions passes it back as reasoning_content, and /alpha/generate carries it as a reasoning block inside the rebuilt assistant turn (the shape the official CLI sends) — a DeepSeek thinking-mode tool loop is rejected without it. Only tool calls with a paired tool result are replayed on either transport.inputSchema, a generated root $ref) no longer fails the whole turn with schema must be a JSON Schema of 'type: "object"'.The plugin only communicates between your local dsh profile and your Command Code account: locally it touches only the credential store and the models cache (plus ~/.commandcode/auth.json as a last-resort fallback); on the network it calls only the Command Code API. No telemetry. With zero data retention on (also off by default), chat requests require a ZDR upstream; models without one fail instead of running without the protection.
Disable without removing: edit your profile's cordis.patch.yml and comment out (or remove) the llm-commandcode row, or set disabled: true, then restart.
Uninstall completely:
dsh plugin --profile web remove @mars-sea/dsh-commandcode-provider
Your API key in the dsh credential store and ~/.commandcode/auth.json are left untouched.
npm install
npm run typecheck # tsc --noEmit
npm run build # tsdown -> lib/
To try a local build in a profile:
dsh plugin --profile web add /path/to/dsh-commandcode-provider
After changing src/, re-run npm run build and restart the app.
MIT — see LICENSE. Portions ported from pi-commandcode-provider (MIT).
Model picker — plan tier, deal/FREE, peak/off-peak, Image and context annotations:
Usage dashboard — /commandcode per-account report:
Settings page — the account list with live quota, model visibility, privacy switches and connection options:
The package exports the plugin root, /client, /locale/*.json, and /package.json. Source remains in the repository; the unpackaged ./src/* export was removed. npm run test:pack checks declared entry points against the actual packed file list.
CLASSIFICATION EVIDENCE
系统优先读取 GitHub Topics,再与站内分类词典和词根规则比对。当前命中: command-code、llm-provider。